accuranker

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is a benign integration guide that instructs an agent to use the official Membrane CLI to access Accuranker API functionality. It does not request unnecessary credentials, does not contain direct exfiltration code, and explicitly recommends letting Membrane manage authentication. The main supply-chain concern is the normal risk of installing a third-party CLI from npm (validate the package owner and version). Overall risk is low but depends on trusting the Membrane service and the npm package integrity.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Faccuranker%2F@ea755f16153e3532539ffa2b07e38f48fcce3929